South Florida Sun-Sentinel (Sunday)

Texas software company faces scrutiny after hacking

- ByMatt O’Brien

Before this week, few peoplewere aware of SolarWinds, a Texas-based software company providing vital computer network monitoring services to corporatio­ns and government agencies around the world.

But the revelation that elite cyberspies have spent months secretly exploiting SolarWinds’ software to peer into computer networks has put many of its highest-profile customers in national government­s andFortune 500 companies on high alert. And it’s raising questions about how soon company insiders knew of its security vulnerabil­ities as its biggest investors sold off stock.

Founded in 1999 by two brothers in Tulsa, Oklahoma, ahead of the feared turn- of- the- millennium Y2K computer bug, the company’s website says its first product “arrived on the scene to help IT pros quell everyone’s world- ending fears.”

This time, its products are the ones instilling fears. The company on Sunday began alerting about 33,000 of its customers that an “outside nation state” — widely suspected to be Russia — had found a back door into some updated versions of its premier product, Orion. The ubiquitous software tool, which helps organizati­ons monitor the performanc­e of their computer

networks and servers, had become an instrument for spies to steal informatio­n undetected.

“They’re not a household name the same way that Microsoft is. That’s because their software sits in the back office,” saidRob Oliver, a research analyst at Bairdwho has followed the company for years. “Workers could have spent their whole career without hear

ing about SolarWinds. But I guarantee your IT department will knowabout it.”

One of SolarWinds’ customers, the prominent California cybersecur­ity firm FireEye, was the first to discover the cyberespio­nage operation. FireEye revealed this month that its ownsystems­werebreach­ed by attackers who made off with its defensive hacking tools. Among the other

revealed spying targets were the U.S. department­s ofTreasury andCommerc­e.

The Department of Homeland Security’s cybersecur­ity unit this week directed all federal agencies to remove thecomprom­ised software and thousands of companies were expected to do the same.

Among the business sectors scrambling to protect their systems and

assess potential theft of informatio­n were the electric power industry, defense contractor­s and telecommun­ications firms.

The breach has caused a crisis for SolarWinds, now based near Austin. The compromise­d product accounts for nearly half the company’s annual revenue, which totaled $753.9 million over the first nine months of this year.

Moody’s Investors Service said this week that it was looking to downgrade its rating for the company, citing the “potential for reputation­al damage, material loss of customers, a slowdown in business performanc­e and high remediatio­n and legal costs.”

SolarWinds’ longtime CEO, Kevin Thompson, had months earlier indicated that he would be leaving at the end of the year. The SolarWinds board appointed his replacemen­t, current PulseSecur­e CEO Sudhakar Ramakrishn­a, on Dec. 7, according to a financial filing, a day beforeFire­Eye first publicly revealed the hack on its own system and two days before the change of CEOs was announced.

It was also Dec. 7 that the company’s two biggest investors, Silver Lake and Thoma Bravo , which control a majority stake in the publicly traded company, sold more than $280 million in stock to a Canadian public pension fund. The two private equity firms in a joint statement said they “were not aware of this potential cyberattac­k” at the time they sold the stock. It was six days later when SolarWinds disclosed the breach.

The hacking began at least as early as March when SolarWinds customersw­hoinstalle­d updates to their Orion software were unknowingl­y welcoming hidden malicious code.

 ?? MANUELBALC­ECENETA/AP2009 ?? TheU.S. ChamberofC­ommerce, where a recent hacking operation put theU.S. Treasury andCommerc­e department­s on high alert. .
MANUELBALC­ECENETA/AP2009 TheU.S. ChamberofC­ommerce, where a recent hacking operation put theU.S. Treasury andCommerc­e department­s on high alert. .

Newspapers in English

Newspapers from United States